tfmcp: Terraform Model Context Protocol Tool
⚠️ This project includes production-ready security features but is still under active development. While the security system provides robust protection, please review all operations carefully in production environments. ⚠️
tfmcp is a command-line tool that helps you interact with Terraform via the Model Context Protocol (MCP). It allows LLMs to manage and operate your Terraform environments, including:
🎮 Demo
See tfmcp in action with Claude Desktop:

- Reading Terraform configuration files
- Analyzing Terraform plan outputs
- Applying Terraform configurations
- Managing Terraform state
- Creating and modifying Terraform configurations
🎉 Latest Release
The latest version of tfmcp (v0.1.6) is now available on Crates.io! You can easily install it using Cargo:
🆕 What's New in v0.1.6
- 🔬 Module Health Analysis: Whitebox IaC approach with cohesion/coupling metrics
- 📊 Resource Dependency Graph: Visualize resource relationships and dependencies
- 🛠️ Refactoring Suggestions: Actionable recommendations with migration steps
- 📦 Module Registry Support: Search and explore Terraform modules
- 📚 MCP Resources: Built-in style guides and best practices documentation
Features
-
🚀 Terraform Integration Deeply integrates with the Terraform CLI to analyze and execute operations.
-
📄 MCP Server Capabilities Runs as a Model Context Protocol server, allowing AI assistants to access and manage Terraform.
-
🔬 Module Health Analysis Whitebox approach to Infrastructure as Code with cohesion/coupling analysis, health scoring, and refactoring suggestions based on software engineering principles.
-
📊 Resource Dependency Graph Visualize resource relationships including explicit depends_on and implicit reference dependencies.
-
📦 Module Registry Integration Search and explore Terraform modules from the registry, get module details and versions.
-
🔐 Enterprise Security Production-ready security controls with configurable policies, audit logging, and access restrictions.
-
📊 Advanced Analysis Detailed Terraform configuration analysis with best practice recommendations and security checks.
-
⚡️ Blazing Fast High-speed processing powered by the Rust ecosystem with optimized parsing and caching.
-
🛠️ Automatic Setup Automatically creates sample Terraform projects when needed, ensuring smooth operation even for new users.
-
🐳 Docker Support Run tfmcp in a containerized environment with all dependencies pre-installed.
Installation
From Source
# Clone the repository
# Build and install
From Crates.io
Using Docker
# Clone the repository
# Build the Docker image
# Run the container
Requirements
- Rust (edition 2021)
- Terraform CLI installed and available in PATH
- Claude Desktop (for AI assistant integration)
- Docker (optional, for containerized deployment)
Usage
)
)
Using Docker
When using Docker, you can run tfmcp commands like this:
# Run as MCP server (default)
# Run with specific command and options
# Mount your Terraform project directory
# Set environment variables
Integrating with Claude Desktop
To use tfmcp with Claude Desktop:
-
If you haven't already, install tfmcp:
Alternatively, you can use Docker:
-
Find the path to your installed tfmcp executable:
-
Add the following configuration to
~/Library/Application\ Support/Claude/claude_desktop_config.json:
If you're using Docker with Claude Desktop, you can set up the configuration like this:
-
Restart Claude Desktop and enable the tfmcp tool.
-
tfmcp will automatically create a sample Terraform project in
~/terraformif one doesn't exist, ensuring Claude can start working with Terraform right away. The sample project is based on the examples included in theexample/demodirectory of this repository.
MCP Tools
tfmcp provides the following MCP tools for AI assistants:
Core Terraform Operations
| Tool | Description |
|---|---|
terraform_init |
Initialize Terraform working directory |
terraform_plan |
Generate and show execution plan |
terraform_apply |
Apply Terraform configuration |
terraform_destroy |
Destroy Terraform-managed infrastructure |
terraform_validate |
Validate configuration syntax |
terraform_state |
Show current state |
list_resources |
List all managed resources |
set_terraform_directory |
Change active project directory |
Module Health Analysis (v0.1.6)
| Tool | Description |
|---|---|
analyze_module_health |
Analyze module health with cohesion/coupling metrics, health score (0-100), issues detection, and recommendations |
get_resource_dependency_graph |
Build resource dependency graph showing nodes, edges (explicit/implicit), and module boundaries |
suggest_module_refactoring |
Generate refactoring suggestions (SplitModule, WrapPublicModule, AddDescriptions, FlattenHierarchy) with migration steps |
Module Registry
| Tool | Description |
|---|---|
search_terraform_modules |
Search Terraform modules in the registry |
get_module_details |
Get detailed information about a module |
get_latest_module_version |
Get the latest version of a module |
get_latest_provider_version |
Get the latest version of a provider |
Provider Information
| Tool | Description |
|---|---|
search_providers |
Search Terraform providers |
get_provider_details |
Get detailed provider information |
list_provider_versions |
List available provider versions |
Logs and Troubleshooting
The tfmcp server logs are available at:
~/Library/Logs/Claude/mcp-server-tfmcp.log
Common issues and solutions:
- Claude can't connect to the server: Make sure the path to the tfmcp executable is correct in your configuration
- Terraform project issues: tfmcp automatically creates a sample Terraform project if none is found
- Method not found errors: MCP protocol support includes resources/list and prompts/list methods
- Docker issues: If using Docker, ensure your container has proper volume mounts and permissions
Environment Variables
Core Configuration
TERRAFORM_DIR: Set this to specify a custom Terraform project directory. If not set, tfmcp will use the directory provided by command line arguments, configuration files, or fall back to~/terraform. You can also change the project directory at runtime using theset_terraform_directorytool.TFMCP_LOG_LEVEL: Set todebug,info,warn, orerrorto control logging verbosity.TFMCP_DEMO_MODE: Set totrueto enable demo mode with additional safety features.
Security Configuration
TFMCP_ALLOW_DANGEROUS_OPS: Set totrueto enable apply/destroy operations (default:false)TFMCP_ALLOW_AUTO_APPROVE: Set totrueto enable auto-approve for dangerous operations (default:false)TFMCP_MAX_RESOURCES: Set maximum number of resources that can be managed (default: 50)TFMCP_AUDIT_ENABLED: Set tofalseto disable audit logging (default:true)TFMCP_AUDIT_LOG_FILE: Custom path for audit log file (default:~/.tfmcp/audit.log)TFMCP_AUDIT_LOG_SENSITIVE: Set totrueto include sensitive information in audit logs (default:false)
Security Considerations
tfmcp includes comprehensive security features designed for production use:
🔒 Built-in Security Features
- Access Controls: Automatic blocking of production/sensitive file patterns
- Operation Restrictions: Dangerous operations (apply/destroy) disabled by default
- Resource Limits: Configurable maximum resource count protection
- Audit Logging: Complete operation tracking with timestamps and user identification
- Directory Validation: Security policy enforcement for project directories
🛡️ Security Best Practices
- Default Safety: Apply/destroy operations are disabled by default - explicitly enable only when needed
- Review Plans: Always review Terraform plans before applying, especially AI-generated ones
- IAM Boundaries: Use appropriate IAM permissions and role boundaries in cloud environments
- Audit Monitoring: Regularly review audit logs at
~/.tfmcp/audit.log - File Patterns: Built-in protection against accessing
prod*,production*, andsecret*patterns - Docker Security: When using containers, carefully consider volume mounts and exposed data
⚙️ Production Configuration
# Recommended production settings
# Keep disabled for safety
# Require manual approval
# Limit resource scope
# Enable audit logging
# Don't log sensitive data
Contributing
Contributions are welcome! Please feel free to submit a Pull Request.
- Fork the repository
- Create your feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add some amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
Roadmap
Here are some planned improvements and future features for tfmcp:
Completed
-
Basic Terraform Integration
Core integration with Terraform CLI for analyzing and executing operations. -
MCP Server Implementation
Initial implementation of the Model Context Protocol server for AI assistants. -
Automatic Project Creation
Added functionality to automatically create sample Terraform projects when needed. -
Claude Desktop Integration
Support for seamless integration with Claude Desktop. -
Core MCP Methods
Implementation of essential MCP methods including resources/list and prompts/list. -
Error Handling Improvements
Better error handling and recovery mechanisms for robust operation. -
Dynamic Project Directory Switching
Added ability to change the active Terraform project directory without restarting the service. -
Crates.io Publication
Published the package to Crates.io for easy installation via Cargo. -
Docker Support
Added containerization support for easier deployment and cross-platform compatibility. -
Security Enhancements Comprehensive security system with configurable policies, audit logging, access controls, and production-ready safety features.
-
Module Health Analysis (v0.1.6) Whitebox approach to IaC with cohesion/coupling metrics, health scoring, and refactoring suggestions.
-
Resource Dependency Graph (v0.1.6) Visualization of resource relationships including explicit and implicit dependencies.
-
Module Registry Integration (v0.1.6) Search and explore Terraform modules from the registry.
-
Comprehensive Testing Framework 74+ tests including integration tests with real Terraform configurations.
In Progress
- Multi-Environment Support Add support for managing multiple Terraform environments, workspaces, and modules.
Planned
-
Expanded MCP Protocol Support Implement additional MCP methods and capabilities for richer integration with AI assistants.
-
Performance Optimization
Optimize resource usage and response times for large Terraform projects. -
Cost Estimation
Integrate with cloud provider pricing APIs to provide cost estimates for Terraform plans. -
Interactive TUI
Develop a terminal-based user interface for easier local usage and debugging. -
Integration with Other AI Platforms
Extend beyond Claude to support other AI assistants and platforms. -
Plugin System
Develop a plugin architecture to allow extensions of core functionality.
License
This project is licensed under the MIT License - see the LICENSE file for details.